First release of LibreSSL portable is available
marc.info
marc.info
1. why CVS sucks and the openbsd team should spend 3 months doing nothing but reworking their development processes so they can use git like all the cool ruby hackers.
2. Lack of formality in the release announcement
3. Choice of font
wow.
Exactly what kind of discussion were you hoping for here? We have a number of individuals frequenting this site with the skills to comment on this at a technical level, but they probably have other things to do then to show up for every story that hits the frontpage of HN and requires someone of their skillset to have a competent discussion of the technical details...
> they can use git like all the cool ruby hackers.
Though git has become widely accepted by the Ruby community, it was created by kernel hackers. Is Linus Torvalds now a 'hipster Ruby hacker' or can we elevate the level of discussion here above name-calling?
It also seems like you've missed comments like this: https://news.ycombinator.com/item?id=8021965
Yes, git did originally come from Linus and the Linux kernel development community. But since then, their original use of it has been eclipsed by the larger and more vocal GitHub/Ruby on Rails/JavaScript segment of software developers. The fact that both groups use git does not mean that they're otherwise connected in any way. Traits (such as the propensity to be a hipster) specific to one of the groups very likely do not apply to the other.
Many of these GitHub/Ruby on Rails/JavaScript people do advocate very loudly for git's use everywhere, even in situations where it is not the best choice, or even where it's obviously a bad choice. Some of them have elevated git from being a tool to a quasi-religion. They've done this with some of their other "chosen" tools, too, so it's not just limited to git.
They do make the git community as a whole look quite bad. But they're obviously very distinct and separate from the Linux kernel developers who created git. The two distinct groups should obviously not be confused.
and why should we trust an SSL tool that uses COMIC SANS on thier website. these LibReSSL dudes sound like idiot hipsters
No, they're just poking fun at people like you :D
Btw, did you have a look into ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/ ?
Unfortunately, without that notice, my first thought was "why is it linking me to an HTTP site". The notice prevents visitors like me from guessing as to why that is by setting the appropriate context and letting us know you're aware of the right steps but they aren't feasible right now.
While LibreSSL does appear to be going in the right direction, especially after the disastrous few months that OpenSSL has had, the community at large does want to be reassured that the LibreSSL project truly does revere security. A more security-conscious release in this case would have helped with that.
However, I really like to download code related to cryptography securely. Perhaps you didn't have the resources or the time to do this.
There were a few easy to do things: posting the hashes of the downloads in various places like GitHub, mailing lists, this HN thread and a few others. GitHub is useful for serving source releases, as long as you post the hashes in more places.
OpenSSL has been heavily criticized. That has been debated ad nauseam in countless places. The one thing I like about OpenSSL is that they're providing secure downloads. Their code might be bad, but at least you can download it from them via HTTPS.
Many would like to contribute, but the OpenBSD project isn't the friendliest (that's a mild way to put it).
It is nevertheless a bit weird to see test sourcecode for TLS support on a site that does not support HTTPS!
Maybe when the cleanup is complete and it's shored up, they might actually use it? :)
I think I prefer BoringSSL's cmake/make process, because OpenSSL's build system is simply horrible, I've never liked it. But it doesn't do shared libraries yet, so I'm having to take the .a files and link them by hand (well, by script anyway). Not optimal, but better than having to rebase my own patches so frequently, and it's only a test box.
I love the sheer amount of renovation-via-demolition libreSSL's doing. OpenSSL really does have a terrifying amount of #if 0, crufty ciphers and code no-one ever wants to use.
By the way, you may as well take RC4 out: it's about to get another significant result...
Like if no RC4 meant no youtube, I don't think we're quite popular enough to demand that youtube change ciphers.
md5/md5_dgst.c: In function 'md5_block_data_order':
md5/md5_dgst.c:107:49: error: right-hand operand of comma expression has no effect [-Werror=unused-value]
HOST_c2l(data,l); X( 0)=l; HOST_c2l(data,l); X( 1)=l;
^Development is done in the upstream OpenBSD codebase. A github clone of the official repositories is kept at: https://github.com/libressl-portable We update this repository from the OpenBSD respositories semi-frequently, so changes may not show up in GitHub immediately. The GitHub repository should be used for informational purposes only.
Really, not having atomic commits is a pain
If he says "we use GNU CVS" you might consider believing him.
-2 for an absolutely true fact? Wow. I'm not normally one to complain about downvotes but.. seriously.
They likely have a toolchain built around CVS that would have a very challenging time being migrated to git.
They also have a workflow that involves tracking file IDs as the import/export files from other projects. Git doesn't do this well.
Again, XP works for many. That doesn't mean there aren't vanishingly few reasons to use it anymore. For CVS, there's the whole non-atomic changes thing, the whole no renaming files thing, no binary file support, no amending commits, no bisect (a feature which I believe sells the software even if everything else sucked), it's harder to collaborate with other users..
Holding onto objectively inferior tools due to a lack of desire to migrate because "it works for me!" is a huge plague on technology.
Or have they implemented something like this on top of CVS?
CVS isn't deprecated. You can't say that it's fundamentally obsolete, either. It's just really primitive, compared to modern DVCS like Git and Mercurial.
But if the primitive functionality fulfills their use case, why should they switch?
* Both are perfectly working versions of software
* Both have been obsoleted by newer, more fully featured, and more secure replacements (git cryptographically hashes its commits, cvs does not)
* Both have users that refuse to migrate from them because "it works for them", despite the benefits and impact on everyone else.
"Unlike Git, you can check out only a subset of the repository."
Maybe useful, you can do that in SVN, also checkouts in GIT are very fast, the point may be moot.
"So I find CVS (and sometimes even RCS) convenient when the repository is a collection of largely unrelated files, and I'm more interested in tracking changes on individual files"
Ok, I guess it makes sense in this strict case (for example, a collection of config files). Apart from that, if you're wondering with version of file A works with which version of file B you lost.
"At least once, I've had to manually reconstruct a saved CVS file that had become corrupted. I'm not sure how I could have done that with SVN or Git."
They wouldn't have corrupted the file in the first place more likely... And yes there are ways to recover it.
As for the (rare) corrupted files, I don't know what caused that. They were single-bit errors that I could correct by manually editing the *,v files. I know of no reason to assume that such errors are more or less likely with Git vs. CVS.
Isn't it? I thought SVN was designed to be a similar but better system? Also cvs(the gpl one, not opencvs) seems to not have had any commits for several years.
And again, they likely also have tools built around CVS. From my understanding of OpenBSD's build system, it would ALSO require significant effort to divorce it from CVS and marry it to git.
Similarly, Arch Linux switching from SVN to git for the packages repositories is very unlikely to happen. They've discussed it a number of times, but besides all the tooling that has been written around the SVN setup, it isn't well-suited to their use case. That isn't to say that switching to git wouldn't have benefits, or that SVN is perfect, but: It would take substantial development and testing effort to make it happen, as well as ALL contributors having to change how they work (not "learn git" (all of the other repositories for Arch are git anyway), but "re-learn all the Arch-specific tools that were built around SVN, but are now built around git").
> Holding onto objectively inferior tools due to a lack of > desire to migrate because "it works for me!" is a huge > plague on technology.
That's a broken argument.
Sure, it is in the case where an organization is hanging onto SVN because none of the developers want to take the effort to switch, and that is a drag on development. But, at the same time, if it is what the developers actually chose; it's not a drag. (The "users refusing to upgrade" is also a drag on technology because of support costs; that is irrelevant here, but is a cause of much of the "must upgrade" feelings among developers)
But the opposite is also true, switching to the latest thing without actually evaluating why is also a HUGE plague on technology. Git in most aspects is a far better tool than CVS. But, there are still things that CVS and SVN are better at (managing subprojects is the biggest one). These are things that I know in Arch mostly outweigh git's benefits, and I presume the same is true of OpenBSD.
It's probably because, true or not, not the best argument. Other than the fact Microsoft ended support Windows XP is fine. It does the job. It's not the latest and greatest, but right to the end it was better than acceptable or tolerable, it was downright decent.
A hardware refresh at work gave me a 7 box, but I've still got my old XP box in a corner somehwere, heavily firewalled ofc now that support has ended, I remote desktop into it 5-10 times a month now for the few straglers I haven't migrated off, and its fine.
Yeah legacy does have support costs, but as I said, you're not building openbsd from source nor would you be if they were on a trendy vcs. That's why they mirror libressl on github, this is a case where they know outsiders might care. And one vcs or another you're going to the mailing list to submit a patch to them, so until you're in it, don't really matter.
CVS works because they didn't fuck it up.
$ uname
OpenBSD
$ cvs -v
Concurrent Versions System (CVS) 1.11.1p1 (client/server)
Copyright (c) 1989-2001 Brian Berliner, david d `zoo' zuhn,
Jeff Polk, and other authors
CVS may be copied only under the terms of the GNU General Public License,
a copy of which can be found with the CVS distribution kit.
Specify the --help option for further information about CVS
Unfortunately CVS isn't the only GPL-licensed piece of software in OpenBSD. But slowly, one by one, these things seem to get replaced with free and better alternatives. I can imagine a future in which we're free of GPL tentacles.Maybe they could switch to a hip, cool font when everything's finished. Right now, it's in Comic Sans territory, because it's really not done.
I guess that makes OpenSSL crayon, I don't know... :) (Kidding!)
By the same token, you're trusting OpenSSL unless you go to great pains not to.